AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Which TWO actions can you perform using Microsoft Sentinel's UEBA (User and Entity Behavior Analytics) feature? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse UEBA's detection-only role with automated response actions (like blocking or disabling accounts), which are separate capabilities in Microsoft Sentinel's automation and playbook features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect anomalous behavior based on historical user activity
Option D is correct because Microsoft Sentinel UEBA builds behavioral baselines from historical log data (sign-in, Azure Activity, Office 365, etc.) and uses machine learning to surface deviations from a user's own normal activity, such as unusual logon times or data volumes. Option E is correct because UEBA also performs peer-group analysis, comparing each user's actions against similar users in the organization to flag anomalous behavior that would not stand out against the user's own baseline. Options A, B, and C are not UEBA capabilities: blocking anonymous-IP sign-ins is done via Conditional Access or named-location policies, running KQL queries across multiple data sources is core Log Analytics/Sentinel hunting (not UEBA-specific), and automatically disabling compromised accounts requires automated response playbooks (Logic Apps) or identity protection tooling, not UEBA itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block sign-ins from anonymous IP addresses
Why it's wrong here
Blocking sign-ins from anonymous IP addresses is an enforcement action that requires Conditional Access policies or Defender for Cloud Apps session controls, not UEBA. UEBA in Microsoft Sentinel is an analytical engine that detects and scores risk based on behavioral anomalies, but it does not natively apply real-time blocks to authentication flows. Therefore, this action does not fall under UEBA capabilities.
- ✗
Run KQL queries to find threats across multiple data sources
Why it's wrong here
Running KQL queries across multiple data sources is a general functionality of Microsoft Sentinel's Log Analytics workspace, applicable to any table, not just UEBA. UEBA's contribution is the generation of BehaviorAnalytics records and Anomalous Activity detections that you can then query, but the querying action itself is not a UEBA feature. The KQL language is a query tool, not a UEBA capability.
- ✗
Automatically disable compromised user accounts
Why it's wrong here
UEBA provides visibility into suspicious behavior but does not take remediation actions such as disabling user accounts. To automatically disable compromised accounts, you would need to configure automation rules or playbooks that invoke actions like Microsoft Graph 'revokeSignInSessions' or a service management action. UEBA itself is read-only and focused on detection, not response.
- ✓
Detect anomalous behavior based on historical user activity
Why this is correct
Microsoft Sentinel UEBA builds a baseline of each user's historical behavior, including sign-in patterns, resource access, and geographic locations, using machine learning. When a user's activity deviates significantly from their own established baseline, UEBA flags it as an anomaly with a risk score. This historical individual baseline is a core mechanism of UEBA, distinguishing it from simple rule-based alerting.
- ✓
Identify users whose activities are anomalous compared to their peers
Why this is correct
Peer-based anomaly detection compares a user's activities against the aggregated behavioral profile of users with similar attributes, such as department, role, or manager, rather than solely against that user's own history. This catches scenarios where a user suddenly behaves like someone in a completely different job function or where an account is compromised and mimics cross-tenant peer patterns. UEBA assigns peer anomaly scores to flag these deviations, which is an essential feature of Sentinel's UEBA implementation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.